<?php
	//Start session
	session_start();
	
	//Include database connection details
	require_once('connection/config.php');
	
	//Connect to mysql server
	$link = mysql_connect(DB_HOST, DB_USER, DB_PASSWORD);
	if(!$link) {
		die('Failed to connect to server: ' . mysql_error());
	}
	
	//Select database
	$db = mysql_select_db(DB_DATABASE);
	if(!$db) {
		die("Unable to select database");
	}
	
	//Function to sanitize values received from the form. Prevents SQL injection
	function clean($str) {
		$str = @trim($str);
		if(get_magic_quotes_gpc()) {
			$str = stripslashes($str);
		}
		return mysql_real_escape_string($str);
	}
	
	//Sanitize the POST values
	$price = clean($_POST['price']);
	$start_date = clean($_POST['startDate']);
	$end_date = clean($_POST['endDate']);

 // check if the 'id' variable is set in URL
 if (isset($_GET['id']))
 {
 // get id value
 $id = $_GET['id'];
 
 // update the entry
 $result = mysql_query("UPDATE specials SET price='$price', start_date='$start_date', end_date='$end_date' WHERE specials_id='$id'")
 or die("There is no record for the id selected ... \n" . mysql_error()); 
 
 // redirect back to the specials page
 header("Location: specials.php");
 }
 else
 // if id isn't set, redirect back to view page
 {
 die("Update failed ... \n" . mysql_error());
 }
 ?>